Build an isolated virtualization environment with Kali Linux, pfSense firewall, and victim virtual machines.
Configure Python security tooling, automated linting, secret detection, and pre-commit security hooks.
Deploy OWASP Juice Shop, DVWA, and Postman API interception proxies for safe vulnerability exploitation.
Provision sandbox AWS/Azure tenant with IAM roles, CloudTrail telemetry, and terraform security scanners.
Configure Elastic Stack/Wazuh SIEM, deploy Sysmon on endpoints, and establish central log pipelines.
Analyze real-world threat actors, MITRE ATT&CK mappings, and Cyber Kill Chain lifecycle stages.
Dissect malicious PCAP files using Wireshark, detect covert channels, and extract payload artifacts.
Apply CIS benchmarks, enforce AppArmor/SELinux, configure auditd, and lock down GPO policies.
Develop automated port scanners, SSL certificate auditors, and password policy validation scripts.
Deploy a private Certificate Authority, implement RSA/AES-GCM encryption routines, and analyze cipher suites.
Execute OWASP Top 10 exploits: SQL Injection, XSS, SSRF, BOLA, and generate remediation advisories.
Conduct passive reconnaissance, digital footprint mapping, and phishing campaign simulation with GoPhish.
Perform Nessus/OpenVAS vulnerability scanning, prioritize CVSS scores, and validate with Metasploit.
Execute Kerberoasting, AS-REP roasting, BloodHound path analysis, and privilege escalation techniques.
Audit cloud misconfigurations, S3 bucket leakages, IAM over-privileges, and implement CSPM automation.
Author Sigma & YARA rules, construct detection dashboards, and fine-tune true/false positive alerts.
Triage memory dumps with Volatility, analyze disk images with Autopsy, and document the incident timeline.
Assess LLM prompt injections, model extraction risks, and align systems with NIST CSF / ISO 27001.